Subscriber Sessions “Online Information Security Sessions from Global Leaders in Information Security Topics.”

Hack ED “Check out our daily articles on Ethical Hacking Education and Discussion Topics!”

Archive for ‘May, 2009’

Microsoft to patch PowerPoint zero-day bug on Tuesday

Microsoft to patch PowerPoint zero-day bug on Tuesday

Microsoft today said it will deliver just one security update next week, a fix for PowerPoint that’s probably the patch for a month-old bug that developers admitted they missed during stress testing. The single update, which will be labeled “critical,” Microsoft’s highest threat ranking, is a big drop from last month, when the company issued [...]

Phished Facebook accounts become spammer’s tool

Phished Facebook accounts become spammer’s tool

Cybercriminals who went after Facebook users with a number of phishing attacks last week have now turned around and begun sending spam messages from the Facebook accounts they cracked. Some of the spam contains “run-of-the mill” Viagra-type messages, but some of it is more dangerous, Facebook spokesman Barry Schnitt said Thursday. “Some of it points [...]

In China, $700 puts a spammer in business

In China, $700 puts a spammer in business

You pay US$700 to use a server in China that lets you send all the spam you like. It’s called bulletproof hosting, and to the people who fight spam and cybercrime it’s becoming a big problem. Cybercriminals use these services not just to host servers, but also to register Internet domain names that they use [...]

BlackBerry Throws iPhone Sales a Curve

BlackBerry Throws iPhone Sales a Curve

The iPhone lost its spot as top-selling phone to the BlackBerry Curve in the first quarter of 2009, but that doesn’t necessarily spell the end of the iPhone’s market dominance, said Ross Rubin, an analyst for researchers The NPD Group. According to an NPD survey, the five top-selling smartphones between Jan. 1 and March 31 [...]

Mobile gym

Mobile gym

The most embraced philosophy these days must be “health is wealth”. Wellness has become a lifestyle to aim for and people are scouring for the best health foods and scurrying to the best fitness centres. Personal trainers have never been more in demand and gyms have never been more crowded. Travellers even pack gym equipment [...]

Open Source Host-based Intrusion Detection System

Open Source Host-based Intrusion Detection System

OSSEC is an Open Source Host-based Intrusion Detection System. It performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. It runs on most operating systems, including Linux, MacOS, Solaris, HP-UX, AIX and Windows. A list with all supported platforms is available here. Click here for information.

First Open Source system for tracking the location of your lost or stolen laptop

First Open Source system for tracking the location of your lost or stolen laptop

Adeona is the first Open Source system for tracking the location of your lost or stolen laptop that does not rely on a proprietary, central service. This means that you can install Adeona on your laptop and go — there’s no need to rely on a single third party. What’s more, Adeona addresses a critical [...]

Linux Kernel “ptrace_attach()” Local Privilege Escalation Vulnerability

Linux Kernel “ptrace_attach()” Local Privilege Escalation Vulnerability

A vulnerability has been identified in Linux Kernel, which could be exploited by a local attacker to gain nelevated privileges. This issue is caused due to the “ptrace_attach()” [kernel/ptrace.c] function using “current->cred_exec_mutex” instead of “task->cred_exec_mutex”, which could allow malicious users to gain root privileges e.g. by combining “ptrace()” and “exec()” calls Click here for information.

Microsoft Lays Off Workers; More Job Cuts Coming?

Microsoft Lays Off Workers; More Job Cuts Coming?

 Microsoft Corp said on Tuesday it is laying off more workers, almost completing its plan to cut 5,000 jobs by June 2010, and left the door open for yet more job cuts. “As we move forward, we will continue to closely monitor the impact of the economic downturn on the company and if necessary, take [...]

Report: U.S. needs ‘transparent’ policies for carrying out cyberattacks

Report: U.S. needs ‘transparent’ policies for carrying out cyberattacks

  The notion that the federal government needs to create an arsenal of cyberattack capabilities to help defend U.S. interests in cyberspace is gaining considerable support as concerns heighten about online security threats aimed at critical infrastructure targets. But the U.S. has no clear legal or policy framework governing the development and use of such [...]